DrByte:
So ... if your issue is that the scanner is absolutely bent on the idea of an email address being ultra-sensitive information, then change the zen_draw_form(FILENAME_CONTACT_US) reference in your template and set its 3rd parameter to 'SSL' instead of 'NONSSL' and this whole problem goes away.
Thank you for your reply, passionate as it is:smile: If I had an ounce of the knowledge you have on the subject, I might be willing to fight that fight with McAfee. Unfortunately, as a lowly shop owner with minimal knowledge and a measly attempt to stay PCI compliant and avoid trouble, I find myself mostly trying to appease them.
As such, if your comments above will work, I would certainly like to try it, but am a little unclear on the exact place and coding format I need. I found this line in my tpl_contact_us_default file in my template:
<?php echo zen_draw_form('contact_us', zen_href_link(FILENAME_CONTACT_US, 'action=send')); ?>
But I do not see a NONSSL reference to change to SSL. A little help if you can as to which file and code line I'm looking for to change would greatly be appreciated.
DrByte:
But, as I said in my first post in this long thread, the information collected is immediately sent off to the storeowner VIA EMAIL ... and we all know that EMAIL is the LEAST SECURE communication method on the internet. So ... protecting the collection of that info by SSL is entirely moot. Especially since THE PERSON GIVING THEIR EMAIL ADDRESS IS EXPECTING YOU TO EMAIL THEM AT SOME POINT. They WANT to be contacted. And they've opted to receive that contact via email. So clearly they don't object to the use of their information being shared in an email. So ... it goes back to the basic question: why is this considered "ultra sensitive" in the first place?
Anyway, rant over.
I suspect that your scanner is not doing its job correctly.
This I agree with, and was my reasoning for requesting a false positive in the first place. Though again, it's not a fight I feel confident in winning. If changing a bit of code somewhere can avoid the fight, I'm willing to go that route and move on. I do thank you for your help. I understand this is a bit of a sensitive discussion with heated opinions on both sides. I'm not strong enough on the subject to pick a side. I just want to be able to submit my little questionnaire and passing pci scan result and move on to the business of shop keeping:P